VYPR

Vendor CVEs

Intel

All CVEs

2,357 total · sorted by risk
  • CVE-2022-34153HigFeb 16, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26343HigFeb 16, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-33176HigNov 11, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-30542HigNov 11, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System R2000WF families before version R02.01.0014 may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2022-29893HigNov 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-26341HigNov 11, 2022
    risk 0.53cvss 8.2epss 0.00

    Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-26006HigNov 11, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-33164HigNov 11, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-40262HigSep 20, 2022
    risk 0.53cvss 8.2epss 0.00

    A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing…

  • CVE-2022-40261HigSep 20, 2022
    risk 0.53cvss 8.2epss 0.00

    An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally…

  • CVE-2022-26873HigSep 20, 2022
    risk 0.53cvss 8.2epss 0.00

    A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing…

  • CVE-2022-32293HigAug 3, 2022
    risk 0.53cvss 8.1epss 0.02

    In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.

  • CVE-2021-33113HigFeb 9, 2022
    risk 0.53cvss 8.1epss 0.01

    Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

  • CVE-2021-0078HigNov 17, 2021
    risk 0.53cvss 8.1epss 0.00

    Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

  • CVE-2021-0133HigJun 9, 2021
    risk 0.53cvss 8.1epss 0.01

    Key exchange without entity authentication in the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-12301HigAug 13, 2020
    risk 0.53cvss 8.2epss 0.00

    Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-12300HigAug 13, 2020
    risk 0.53cvss 8.2epss 0.00

    Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-12299HigAug 13, 2020
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-8722HigAug 13, 2020
    risk 0.53cvss 8.2epss 0.00

    Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-8721HigAug 13, 2020
    risk 0.53cvss 8.2epss 0.00

    Improper input validation for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-8719HigAug 13, 2020
    risk 0.53cvss 8.2epss 0.00

    Buffer overflow in subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-17497HigAug 12, 2020
    risk 0.53cvss 8.1epss 0.01

    eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.

  • CVE-2019-0131HigDec 18, 2019
    risk 0.53cvss 8.1epss 0.01

    Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

  • CVE-2019-0142HigNov 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2019-11178HigNov 14, 2019
    risk 0.53cvss 8.1epss 0.01

    Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/or denial of service via network access.

  • CVE-2019-11137HigNov 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user…

  • CVE-2019-0163HigApr 17, 2019
    risk 0.53cvss 8.2epss 0.00

    Insufficient input validation in system firmware for Intel(R) Broadwell U i5 vPro before version MYBDWi5v.86A may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

  • CVE-2018-12220HigMar 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Logic bug in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a…

  • CVE-2018-12216HigMar 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a…

  • CVE-2018-12214HigMar 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Potential memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a…

  • CVE-2018-3643HigSep 12, 2018
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker…

  • CVE-2018-12176HigSep 12, 2018
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

  • CVE-2018-3682HigJul 10, 2018
    risk 0.53cvss 8.2epss 0.00

    BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized read\writes to the SMBUS.

  • CVE-2018-3627HigJul 10, 2018
    risk 0.53cvss 8.2epss 0.01

    Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access.

  • CVE-2016-8022HigMar 14, 2017
    risk 0.53cvss 7.5epss 0.13

    Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary code or cause a denial of service via a crafted authentication cookie.

  • CVE-2016-5672HigAug 1, 2016
    risk 0.53cvss 8.1epss 0.02

    Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it…

  • CVE-2025-20046HigMay 13, 2025
    risk 0.52cvss 8.0epss 0.00

    Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-39368HigNov 13, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-26513HigNov 11, 2022
    risk 0.52cvss 8.0epss 0.00

    Out-of-bounds write in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-26017HigAug 18, 2022
    risk 0.52cvss 8.0epss 0.00

    Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-21225HigAug 18, 2022
    risk 0.52cvss 8.0epss 0.02

    Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-0126HigMay 12, 2022
    risk 0.52cvss 8.0epss 0.00

    Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2020-24474HigJun 9, 2021
    risk 0.52cvss 8.0epss 0.00

    Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2019-14557HigOct 5, 2020
    risk 0.52cvss 8.0epss 0.01

    Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access.

  • CVE-2019-0096HigMay 17, 2019
    risk 0.52cvss 8.0epss 0.01

    Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an authenticated user to potentially enable escalation of privilege via adjacent network access.

  • CVE-2018-3662HigAug 1, 2018
    risk 0.52cvss 8.0epss 0.01

    Escalation of privilege in Intel Saffron MemoryBase before version 11.4 potentially allows an authorized user of the Saffron application to execute arbitrary code as root.

  • CVE-2026-20767HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable…

  • CVE-2026-20714HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation…

  • CVE-2025-35998HigFeb 10, 2026
    risk 0.51cvss 7.9epss 0.00

    Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack…

  • CVE-2025-30513HigFeb 10, 2026
    risk 0.51cvss 7.9epss 0.00

    Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when…

Page 5 of 48